PkgRadar

npm · registry.npmjs.org

qwen-code-webui

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.2.32

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/static/assets/index-Cw2UKNSA.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/static/assets/index-Cw2UKNSA.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/cli/node.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.35Low risk02026-06-03
0.2.34Low risk02026-05-31
0.2.32Review422026-05-25
0.2.33Review542026-05-25

Related campaigns

Block this in CI

PkgRadar gates qwen-code-webui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]